<HTML><HEAD>
<META HTTP-EQUIV="refresh" CONTENT="0; URL=http://example.com;URL=javascript:alert(413);"></META>
</HEAD><BODY>

Test 413.  XSS in Refresh header tokenization.  Thanks to
Google Browser security handbook.
</BODY></HTML>
